Identity verification method and system based on homomorphic encryption

Through the homomorphic encryption method, the client encrypts and transmits the user password and combines random challenge values to calculate it, solving the security risks of the traditional username-password mechanism, realizing the privacy protection of user passwords and preventing playback attacks, and improving the security and data integrity of network identity authentication.

CN120455125APending Publication Date: 2025-08-08LINGSHU TECH CO LTD

Patent Information

Application Number
CN202510726514.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-03
Publication Date
2025-08-08

AI Technical Summary

Technical Problem

The traditional username-password mechanism has user credential transmission risks, database leakage threats and replay attack vulnerabilities in network identity authentication, resulting in significant security risks.

Method used

The identity authentication method based on homomorphic encryption is adopted, and the public and private keys are generated by the server. The client encrypts the user password, generates and transmits the ciphertext, and homomorphic calculation is performed with random challenge values. The server verifies the difference ciphertext to complete identity authentication, ensuring that the password is always transmitted and stored in ciphertext form, and prevents plaintext leakage and replay attacks.

Benefits of technology

It realizes the privacy protection of user passwords, prevents attacks by man-in-the-middle and data tampering, ensures the uniqueness of each authentication request, reduces the pressure on sensitive data processing on the server, improves data security and prevents playback attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120455125A_ABST
    Figure CN120455125A_ABST
Patent Text Reader

Abstract

The invention discloses an identity verification method and system based on homomorphic encryption. The method comprises the steps that a server side generates a public key and a private key, during registration, a client side obtains the public key, a unique identifier input by a user and a password, and the public key is used for encrypting the password to obtain a first ciphertext; storing the first ciphertext and the unique identifier in a database of a server; during login, the client obtains a unique identifier and a password input by a user, the server generates a random challenge value and sends the random challenge value to the client, the client encrypts the password by using the public key to obtain a second ciphertext, and a third ciphertext is calculated according to the second ciphertext and the random challenge value; the server obtains the third ciphertext and the unique identifier, and obtains the first ciphertext from the database according to the unique identifier; calculating according to the first ciphertext and the random challenge value to obtain a fourth ciphertext; obtaining a difference ciphertext according to the third ciphertext and the fourth ciphertext; and if the difference ciphertext is 0, the user identity authentication is passed. According to the method, the server side cannot acquire the plaintext, and privacy is guaranteed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to a homomorphic encryption-based identity authentication method and system. Background Art

[0002] In the current online identity authentication system, the traditional username-password mechanism presents significant security risks. In a typical process, the client transmits user credentials in plain text to the server, which then verifies the credentials and returns the login result. However, this mechanism has three vulnerabilities:

[0003] (1) User credentials may be intercepted or tampered with by a man-in-the-middle attack during transmission;

[0004] (2) If the server stores passwords in plain text, a database leak will lead to a large-scale privacy crisis;

[0005] (3) An attacker can use replay attacks to forge legitimate sessions. Summary of the Invention

[0006] The embodiments of the present invention provide a homomorphic encryption-based identity authentication method and system to solve the problems of user credential transmission risks, database leakage threats, and replay attack vulnerabilities in the prior art.

[0007] To achieve the above-mentioned purpose, on the one hand, the present invention provides an identity authentication method based on homomorphic encryption, which includes: S1, the server generates a public key and a private key and stores them locally; S2, the client obtains the public key of the server, obtains the unique identifier and password entered by the user when registering; uses the public key to encrypt the password to obtain a first ciphertext; S3, the server obtains the first ciphertext and the unique identifier entered when registering and stores them in a database; S4, the client obtains the unique identifier entered by the user when logging in and sends it to the server; the server generates a random challenge value and binds it to the unique identifier; the server sends the random challenge value to the server; Sent to the client; the client obtains the password entered by the user when logging in, encrypts the password with the public key, and obtains the second ciphertext; the client calculates the third ciphertext based on the second ciphertext and the random challenge value; S5, the server obtains the third ciphertext and the unique identifier entered when logging in, and obtains the first ciphertext from the database according to the unique identifier entered when logging in; the server calculates the fourth ciphertext based on the first ciphertext and the random challenge value bound to the unique identifier; S6, the server calculates the difference ciphertext based on the third ciphertext and the fourth ciphertext; if the difference ciphertext is 0, the user identity authentication is passed, and the random challenge value is deleted at the same time.

[0008] Optionally, the server obtaining the first ciphertext and the unique identifier entered during registration and storing them in a database includes: the client concatenating the unique identifier, public key, first ciphertext, and timestamp entered during registration to generate a first signature; the client sending the unique identifier, public key, first ciphertext, timestamp, and first signature entered during registration as first packaged data to the server; the server verifying whether the first packaged data transmitted by the client has been tampered with; if not, storing the unique identifier entered during registration and the first ciphertext in the database;

[0009] The server obtains the third ciphertext and the unique identifier entered during login, and obtains the first ciphertext from the database according to the unique identifier entered during login, including: the client concatenates the unique identifier, public key, third ciphertext, and timestamp entered during login and generates a second signature; the client sends the unique identifier, public key, third ciphertext, timestamp, and second signature entered during login as second packaged data to the server; the server verifies whether the second packaged data transmitted by the client has been tampered with; if not, obtains the first ciphertext from the database according to the unique identifier entered during login.

[0010] Optionally, the server verifies whether the first packaged data transmitted by the client has been tampered with; if not, storing the unique identifier entered during registration and the first ciphertext in the database includes: the server concatenates the unique identifier entered during registration, the public key, the first ciphertext, and the timestamp in the first packaged data transmitted by the client and generates a third signature; the server verifies whether the third signature is consistent with the first signature in the first packaged data transmitted by the client, and verifies whether the locally stored public key is consistent with the public key in the first packaged data transmitted by the client; if they are consistent, storing the unique identifier entered during registration and the first ciphertext in the database;

[0011] The server verifies whether the second packaged data transmitted by the client has been tampered with; if not, obtaining the first ciphertext from the database according to the unique identifier entered during login, including: the server concatenates the unique identifier entered during login, the public key, the third ciphertext, and the timestamp in the second packaged data transmitted by the client and generates a fourth signature; the server verifies whether the fourth signature is consistent with the second signature in the second packaged data transmitted by the client, and verifies whether the locally stored public key is consistent with the public key in the second packaged data transmitted by the client; if they are all consistent, obtaining the first ciphertext from the database according to the unique identifier entered during login.

[0012] Optionally, S1 includes: the server randomly generates two large prime numbers p and q, and satisfies gcd(pq, (p-1)(q-1))=1; generates a public key and a private key according to the two large prime numbers p and q and stores them locally.

[0013] Optionally, the third ciphertext is calculated according to the following formula:

[0014] m1=E(P′)·E(C)modn 2

[0015] Where m1 is the third ciphertext, E(P′) is the second ciphertext, C is the random challenge value, P′ is the password entered by the user when logging in, n is the product of two large prime numbers p and q, and mod is the remainder;

[0016] The fourth ciphertext is calculated according to the following formula:

[0017] m2=E(P)·E(C)modn 2

[0018] Among them, m2 is the fourth ciphertext, E(P) is the first ciphertext, C is the random challenge value, P is the password entered by the user when registering, n is the product of two large prime numbers p and q, and mod is the remainder.

[0019] On the other hand, the present invention provides an identity authentication system based on homomorphic encryption, which includes: a generation unit for generating a public key and a private key on the server side and storing them locally; a first encryption unit for obtaining the public key of the server side from the client side, and obtaining the unique identifier and password entered by the user when registering; encrypting the password with the public key to obtain a first ciphertext; a storage unit for obtaining the first ciphertext and the unique identifier entered when registering from the server side and storing them in a database; a second encryption unit for obtaining the unique identifier entered by the user when logging in from the client side and sending it to the server side; the server side generates a random challenge value and binds it to the unique identifier; the server side encrypts the random challenge value The value is sent to the client; the client obtains the password entered by the user when logging in, encrypts the password with the public key, and obtains a second ciphertext; the client calculates a third ciphertext based on the second ciphertext and the random challenge value; the third encryption unit is used for the server to obtain the third ciphertext and the unique identifier entered when logging in, and obtain the first ciphertext from the database according to the unique identifier entered when logging in; the server calculates a fourth ciphertext based on the first ciphertext and the random challenge value bound to the unique identifier; the verification unit is used for the server to calculate a difference ciphertext based on the third ciphertext and the fourth ciphertext; if the difference ciphertext is 0, the user identity authentication is passed, and the random challenge value is deleted at the same time.

[0020] Optionally, the server obtaining the first ciphertext and the unique identifier entered during registration and storing them in a database includes: the client concatenating the unique identifier, public key, first ciphertext, and timestamp entered during registration to generate a first signature; the client sending the unique identifier, public key, first ciphertext, timestamp, and first signature entered during registration as first packaged data to the server; the server verifying whether the first packaged data transmitted by the client has been tampered with; if not, storing the unique identifier entered during registration and the first ciphertext in the database;

[0021] The server obtains the third ciphertext and the unique identifier entered during login, and obtains the first ciphertext from the database according to the unique identifier entered during login, including: the client concatenates the unique identifier, public key, third ciphertext, and timestamp entered during login and generates a second signature; the client sends the unique identifier, public key, third ciphertext, timestamp, and second signature entered during login as second packaged data to the server; the server verifies whether the second packaged data transmitted by the client has been tampered with; if not, obtains the first ciphertext from the database according to the unique identifier entered during login.

[0022] Optionally, the server verifies whether the first packaged data transmitted by the client has been tampered with; if not, storing the unique identifier entered during registration and the first ciphertext in the database includes: the server concatenates the unique identifier entered during registration, the public key, the first ciphertext, and the timestamp in the first packaged data transmitted by the client and generates a third signature; the server verifies whether the third signature is consistent with the first signature in the first packaged data transmitted by the client, and verifies whether the locally stored public key is consistent with the public key in the first packaged data transmitted by the client; if they are consistent, storing the unique identifier entered during registration and the first ciphertext in the database;

[0023] The server verifies whether the second packaged data transmitted by the client has been tampered with; if not, obtaining the first ciphertext from the database according to the unique identifier entered during login, including: the server concatenates the unique identifier entered during login, the public key, the third ciphertext, and the timestamp in the second packaged data transmitted by the client and generates a fourth signature; the server verifies whether the fourth signature is consistent with the second signature in the second packaged data transmitted by the client, and verifies whether the locally stored public key is consistent with the public key in the second packaged data transmitted by the client; if they are all consistent, obtaining the first ciphertext from the database according to the unique identifier entered during login.

[0024] Optionally, the generation unit includes: a first generation subunit, used for the server to randomly generate two large prime numbers p and q, and satisfy gcd(pq, (p-1)(q-1)) = 1; a second generation subunit, used to generate a public key and a private key based on the two large prime numbers p and q and store them locally.

[0025] Optionally, the third ciphertext is calculated according to the following formula:

[0026] m1=E(P′)·E(C)modn 2

[0027] Where m1 is the third ciphertext, E(P′) is the second ciphertext, C is the random challenge value, P′ is the password entered by the user when logging in, n is the product of two large prime numbers p and q, and mod is the remainder;

[0028] The fourth ciphertext is calculated according to the following formula:

[0029] m2=E(P)·E(C)modn 2

[0030] Among them, m2 is the fourth ciphertext, E(P) is the first ciphertext, C is the random challenge value, P is the password entered by the user when registering, n is the product of two large prime numbers p and q, and mod is the remainder.

[0031] Beneficial effects of the present invention:

[0032] The present invention provides an identity authentication method and system based on homomorphic encryption, in which the user password of this method is always transmitted and stored in ciphertext form, and the server cannot obtain the plaintext; even if the server database is leaked, the attacker cannot deduct the plaintext password from the ciphertext; the ciphertext is further encrypted by a random challenge value to prevent replay attacks and ensure that each authentication request is unique and cannot be forged. BRIEF DESCRIPTION OF THE DRAWINGS

[0033] Figure 1 This is a flowchart of a homomorphic encryption-based identity authentication method provided by an embodiment of the present invention;

[0034] Figure 2 It is a structural diagram of a homomorphic encryption-based identity authentication system provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0035] To make the objectives, technical solutions, and advantages of the present invention more apparent, the present invention will be further described in detail below with reference to the accompanying drawings. It is apparent that the embodiments described are only some, not all, of the present invention. All other embodiments derived by persons of ordinary skill in the art based on the embodiments of the present invention without creative effort are intended to fall within the scope of protection of the present invention.

[0036] Figure 1 This is an authentication method based on homomorphic encryption provided by an embodiment of the present invention. Figure 1 As shown, the method includes:

[0037] S1. The server generates public and private keys and stores them locally.

[0038] In an optional embodiment, the S1 includes:

[0039] The server randomly generates two large prime numbers p and q, and satisfies gcd(pq,(p-1)(q-1))=1;

[0040] Specifically, gcd stands for greatest common divisor, which refers to the largest common factor between two integers. gcd(pq,(p-1)(q-1)) = 1 means that the two positive integers pq and (p-1)(q-1) are relatively prime, meaning their greatest common divisor is 1, ensuring key security.

[0041] Generate public and private keys based on two large prime numbers p and q and store them locally.

[0042] First, calculate n = p * q, where n is part of the public key; the public key pk = (n, g), where g is usually chosen to be n + 1.

[0043] Next, calculate λ=lcm(p-1,q-1); where lcm is the least common multiple; and the private key sk=λ.

[0044] Store the public and private keys securely on the server.

[0045] Furthermore, a challenge value generator (such as a random number generator based on a hash function) is initialized on the server side. The challenge value generator is used to generate a unique, unpredictable random challenge value for each user session during the authentication process to ensure the uniqueness of the authentication request.

[0046] S2. The client obtains the public key of the server and obtains the unique identifier and password entered by the user during registration; encrypts the password using the public key to obtain a first ciphertext;

[0047] In an optional embodiment, during registration, the client obtains the server's public key pk = (n, g); the user enters a password P and a unique identifier on the client, and the client encrypts the password P using the public key to obtain a first ciphertext; wherein the unique identifier is generally a string such as a user name, email address, or mobile phone number, which is used to uniquely identify the user;

[0048] The first ciphertext is calculated according to the following formula:

[0049]

[0050] Among them, E(P) is the first ciphertext, P is the password entered by the user during registration, n is the product of two large prime numbers p and q, g is n+1, r1 is a random number, and mod is the remainder.

[0051] S3. The server obtains the first ciphertext and the unique identifier entered during registration and stores them in the database;

[0052] In an optional embodiment, the server obtains the first ciphertext and the unique identifier entered during registration and stores them in a database, including:

[0053] (1) The client concatenates the unique identifier, public key, first ciphertext, and timestamp entered during registration to generate a first signature;

[0054] Specifically, the client concatenates the unique identifier, public key, first ciphertext, and timestamp entered during registration, hashes or asymmetric encrypts the concatenated string, and generates a first signature.

[0055] (2) The client sends the unique identifier, public key, first ciphertext, timestamp, and first signature entered during registration as first packaged data to the server;

[0056] (3) The server verifies whether the first packaged data transmitted by the client has been tampered with; if not, the server stores the unique identifier and the first ciphertext entered during registration in the database.

[0057] In an optional embodiment, the server verifies whether the first packaged data transmitted by the client has been tampered with; if not, storing the unique identifier and the first ciphertext entered during registration in a database includes:

[0058] ① The server concatenates the unique identifier, public key, first ciphertext, and timestamp entered during registration in the first packaged data transmitted by the client and generates a third signature;

[0059] ② The server verifies whether the third signature is consistent with the first signature in the first packaged data transmitted by the client, and verifies whether the locally stored public key is consistent with the public key in the first packaged data transmitted by the client; if they are consistent, the unique identifier and the first ciphertext entered during registration are stored in the database;

[0060] Specifically, the server verifies whether the third signature is consistent with the first signature, and verifies whether the locally stored public key is consistent with the transmitted public key. If they are consistent, it means that the first packaged data (including: the unique identifier entered during registration, public key, first ciphertext, timestamp, and first signature) has not been tampered with during transmission. After successful verification, the unique identifier entered during registration and the first ciphertext are stored in the server's database. The server stores the first ciphertext and does not save the plaintext password and random number r1. Therefore, even if the server's database is leaked, an attacker cannot reverse the plaintext password from the first ciphertext. If there is any inconsistency, the verification fails, the user registration is denied, and the abnormal behavior is recorded.

[0061] S4. The client obtains the unique identifier entered by the user when logging in and sends it to the server; the server generates a random challenge value and binds it to the unique identifier; the server sends the random challenge value to the client; the client obtains the password entered by the user when logging in, encrypts the password using the public key to obtain a second ciphertext; the client calculates a third ciphertext based on the second ciphertext and the random challenge value;

[0062] In an optional embodiment, when logging in, the user initiates a request to the client, and the client obtains the unique identifier entered by the user when logging in and sends it to the server;

[0063] The server generates a random challenge value C through a challenge value generator, and binds the random challenge value C to the unique identifier entered during login; the server sends the random challenge value C to the client.

[0064] The client obtains the password P' entered by the user when logging in, and encrypts the password P' using the public key to obtain a second ciphertext;

[0065] The second ciphertext is calculated according to the following formula:

[0066]

[0067] Where E(P′) is the second ciphertext, P′ is the password entered by the user when logging in, n is the product of two large prime numbers p and q, g is n+1, r2 is a random number, and mod is the remainder.

[0068] The client performs homomorphic computation to generate the third ciphertext, that is, the third ciphertext is calculated based on the second ciphertext and the random challenge value C;

[0069] The third ciphertext is calculated according to the following formula:

[0070] m1=E(P′)·E(C)modn 2

[0071] Among them, m1 is the third ciphertext, E(P′) is the second ciphertext, C is the random challenge value, P′ is the password entered by the user when logging in, n is the product of two large prime numbers p and q, and mod is the remainder.

[0072] S5. The server obtains the third ciphertext and the unique identifier entered during login, and obtains the first ciphertext from the database based on the unique identifier entered during login. The server calculates the fourth ciphertext based on the first ciphertext and the random challenge value bound to the unique identifier.

[0073] In an optional embodiment, the server obtains the third ciphertext and the unique identifier entered during login, and obtains the first ciphertext from the database according to the unique identifier entered during login, including:

[0074] (1) The client concatenates the unique identifier, public key, third ciphertext, and timestamp entered during login to generate a second signature;

[0075] Specifically, the client concatenates the unique identifier, public key, third ciphertext, and timestamp entered during login, hashes or asymmetric encrypts the concatenated string, and generates a second signature.

[0076] (2) The client sends the unique identifier, public key, third ciphertext, timestamp, and second signature entered during login to the server as second packaged data;

[0077] (3) The server verifies whether the second packaged data transmitted by the client has been tampered with; if not, the server obtains the first ciphertext from the database according to the unique identifier entered during login.

[0078] In an optional embodiment, the server verifies whether the second packaged data transmitted by the client has been tampered with; if not, obtaining the first ciphertext from the database according to the unique identifier entered during login includes:

[0079] ① The server concatenates the unique identifier, public key, third ciphertext, and timestamp entered during login in the second packaged data transmitted by the client and generates a fourth signature;

[0080] ② The server verifies whether the fourth signature is consistent with the second signature in the second packaged data transmitted by the client, and verifies whether the locally stored public key is consistent with the public key in the second packaged data transmitted by the client; if they are consistent, the server obtains the first ciphertext from the database according to the unique identifier entered during login.

[0081] Specifically, the server verifies whether the fourth signature is consistent with the second signature, and verifies whether the locally stored public key is consistent with the transmitted public key. If they are consistent, it means that the second packaged data (including: the unique identifier entered at login, the public key, the third ciphertext, the timestamp, and the second signature) has not been tampered with during transmission. After the verification is successful, the first ciphertext is obtained from the server's database based on the unique identifier entered by the user at login; that is, the unique identifier entered by the user at login is the same as the unique identifier entered when the user registered, so the corresponding first ciphertext can be found based on the unique identifier. If there is an inconsistency, the verification fails, the user is denied login, and the abnormal behavior is recorded.

[0082] The server calculates a fourth ciphertext based on the first ciphertext and a random challenge value C bound to the unique identifier entered during login.

[0083] The fourth ciphertext is calculated according to the following formula:

[0084] m2=E(P)·E(C)modn 2

[0085] Among them, m2 is the fourth ciphertext, E(P) is the first ciphertext, C is the random challenge value, P is the password entered by the user when registering, n is the product of two large prime numbers p and q, and mod is the remainder.

[0086] S6. The server calculates the difference ciphertext based on the third ciphertext and the fourth ciphertext; if the difference ciphertext is 0, the user identity authentication is passed, and the random challenge value is deleted.

[0087] In an optional embodiment, the difference ciphertext is calculated according to the following formula:

[0088] Δ=D(m1·m2)

[0089] The difference ciphertext is Δ, m1 is the third ciphertext, and m2 is the fourth ciphertext.

[0090] If the difference ciphertext Δ = 0, then the password P entered by the user during registration = the password P′ entered by the user during login, the user identity authentication is passed, and the random challenge value C is deleted or set to expire. Otherwise, the user login is denied.

[0091] In the above method, the client calculates the third ciphertext, and the server uses the homomorphism principle to calculate the fourth ciphertext. The fourth ciphertext is directly compared with the third ciphertext. Identity verification can be completed without restoring the plaintext password, effectively protecting the privacy of the user's password.

[0092] Further, once the user's identity is authenticated, the server generates a token and sends it to the client. A token is an authentication token used to identify the user's session status between the client and the server. It is essentially an encrypted string or identifier used to prove that the client has passed the authentication process.

[0093] Figure 2 This is a schematic diagram of the structure of a homomorphic encryption-based identity authentication system provided by an embodiment of the present invention. Figure 2 As shown, the system includes:

[0094] Generating unit 201, used for the server to generate public and private keys and store them locally;

[0095] The first encryption unit 202 is used for the client to obtain the public key of the server, obtain the unique identifier and password entered by the user during registration, and encrypt the password using the public key to obtain a first ciphertext;

[0096] Storage unit 203, used for the server to obtain the first ciphertext and the unique identifier entered during registration and store them in a database;

[0097] The second encryption unit 204 is configured to cause the client to obtain the unique identifier entered by the user during login and send it to the server; the server to generate a random challenge value and bind it to the unique identifier; the server to send the random challenge value to the client; the client to obtain the password entered by the user during login and encrypt the password using the public key to obtain a second ciphertext; the client to calculate a third ciphertext based on the second ciphertext and the random challenge value;

[0098] The third encryption unit 205 is used for the server to obtain the third ciphertext and the unique identifier entered during login, and obtain the first ciphertext from the database based on the unique identifier entered during login; the server calculates the fourth ciphertext based on the first ciphertext and the random challenge value bound to the unique identifier;

[0099] The verification unit 206 is used for the server to calculate the difference ciphertext based on the third ciphertext and the fourth ciphertext; if the difference ciphertext is 0, the user identity authentication is passed and the random challenge value is deleted.

[0100] In an optional embodiment, the server obtains the first ciphertext and the unique identifier entered during registration and stores them in a database, including:

[0101] The client concatenates the unique identifier, public key, first ciphertext, and timestamp entered during registration to generate the first signature;

[0102] The client sends the unique identifier, public key, first ciphertext, timestamp, and first signature entered during registration as first packaged data to the server;

[0103] The server verifies whether the first packaged data transmitted by the client has been tampered with; if not, the server stores the unique identifier and the first ciphertext entered during registration in the database;

[0104] The server obtains the third ciphertext and the unique identifier input during login, and obtains the first ciphertext from the database according to the unique identifier input during login, including:

[0105] The client concatenates the unique identifier, public key, third ciphertext, and timestamp entered during login to generate a second signature.

[0106] The client sends the unique identifier, public key, third ciphertext, timestamp, and second signature entered during login to the server as second packaged data;

[0107] The server verifies whether the second packaged data transmitted by the client has been tampered with; if not, it obtains the first ciphertext from the database according to the unique identifier entered during login.

[0108] In an optional embodiment, the server verifies whether the first packaged data transmitted by the client has been tampered with; if not, storing the unique identifier and the first ciphertext entered during registration in a database includes:

[0109] The server concatenates the unique identifier, public key, first ciphertext, and timestamp entered during registration in the first packaged data transmitted by the client and generates a third signature;

[0110] The server verifies whether the third signature is consistent with the first signature in the first packaged data transmitted by the client, and verifies whether the locally stored public key is consistent with the public key in the first packaged data transmitted by the client; if they are consistent, the unique identifier and the first ciphertext entered during registration are stored in the database;

[0111] The server verifies whether the second packaged data transmitted by the client has been tampered with; if not, obtaining the first ciphertext from the database according to the unique identifier entered during login includes:

[0112] The server concatenates the unique identifier, public key, third ciphertext, and timestamp entered during login in the second packaged data transmitted by the client and generates a fourth signature;

[0113] The server verifies whether the fourth signature is consistent with the second signature in the second packaged data transmitted by the client, and verifies whether the locally stored public key is consistent with the public key in the second packaged data transmitted by the client; if they are consistent, the server obtains the first ciphertext from the database according to the unique identifier entered during login.

[0114] In an optional embodiment, the generating unit 201 includes:

[0115] The first generation subunit is used for the server to randomly generate two large prime numbers p and q, and satisfy gcd(pq, (p-1)(q-1)) = 1;

[0116] The second generation subunit is used to generate a public key and a private key according to two large prime numbers p and q and store them locally.

[0117] In an optional embodiment, the third ciphertext is calculated according to the following formula:

[0118] m1=E(P′)·E(C)modn 2

[0119] Where m1 is the third ciphertext, E(P′) is the second ciphertext, C is the random challenge value, P′ is the password entered by the user when logging in, n is the product of two large prime numbers p and q, and mod is the remainder;

[0120] The fourth ciphertext is calculated according to the following formula:

[0121] m2=E(P)·E(C)modn 2

[0122] Among them, m2 is the fourth ciphertext, E(P) is the first ciphertext, C is the random challenge value, P is the password entered by the user when registering, n is the product of two large prime numbers p and q, and mod is the remainder.

[0123] The system of the present invention corresponds to the method of the present invention, and the specific implementation of the system will not be repeated here.

[0124] Beneficial effects of the present invention:

[0125] (1) Significantly improve data security and avoid plaintext leakage: The user password is encrypted on the client side and transmitted to the server in ciphertext form. The server cannot obtain the plaintext; even if the server database is leaked, the attacker cannot reverse the plaintext password from the ciphertext; effectively prevent large-scale privacy leakage.

[0126] (2) Prevent man-in-the-middle attacks and data tampering: The integrity of some packaged data (unique identifier, public key, ciphertext, timestamp, etc.) is verified through a signature mechanism; if the data is tampered with during transmission, the server can detect and reject illegal requests through signature verification and public key verification.

[0127] (3) Effectively prevent replay attacks: Each time a user logs in, the server generates a unique random challenge value; the client response includes a homomorphic calculation involving the random challenge value, ensuring that the authentication request is one-time and one-key, preventing attackers from reusing old request data.

[0128] (4) Remote verification based on homomorphic encryption without decrypting plaintext: The present invention uses the Paillier homomorphic encryption algorithm to complete identity verification without the server knowing the plaintext password; it reduces the pressure on the server to process sensitive data and reduces the risk of attack.

[0129] (5) After the user passes the authentication, a token is returned, which can be used for subsequent password-free access;

[0130] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present invention.

Claims

1. A homomorphic encryption-based identity authentication method, characterized in that: include: S1. The server generates public and private keys and stores them locally. S2. The client obtains the public key of the server and the unique ID and password entered by the user during registration; Encrypt the password using the public key to obtain a first ciphertext; S3. The server obtains the first ciphertext and the unique identifier entered during registration and stores them in the database; S4. The client obtains the unique identifier entered by the user when logging in and sends it to the server; the server generates a random challenge value and binds it to the unique identifier; the server sends the random challenge value to the client; The client obtains the password entered by the user when logging in, and encrypts the password using the public key to obtain a second ciphertext; The client calculates the third ciphertext based on the second ciphertext and the random challenge value; S5. The server obtains the third ciphertext and the unique identifier entered during login, and obtains the first ciphertext from the database based on the unique identifier entered during login. The server calculates the fourth ciphertext based on the first ciphertext and the random challenge value bound to the unique identifier. S6. The server calculates the difference ciphertext based on the third ciphertext and the fourth ciphertext; if the difference ciphertext is 0, the user identity authentication is passed, and the random challenge value is deleted.

2. The method according to claim 1, wherein: The server obtains the first ciphertext and the unique identifier entered during registration and stores them in the database, including: The client concatenates the unique identifier, public key, first ciphertext, and timestamp entered during registration to generate the first signature; The client sends the unique identifier, public key, first ciphertext, timestamp, and first signature entered during registration as first packaged data to the server; The server verifies whether the first packaged data transmitted by the client has been tampered with; if not, the server stores the unique identifier and the first ciphertext entered during registration in the database; The server obtains the third ciphertext and the unique identifier input during login, and obtains the first ciphertext from the database according to the unique identifier input during login, including: The client concatenates the unique identifier, public key, third ciphertext, and timestamp entered during login to generate a second signature. The client sends the unique identifier, public key, third ciphertext, timestamp, and second signature entered during login to the server as second packaged data; The server verifies whether the second packaged data transmitted by the client has been tampered with; if not, it obtains the first ciphertext from the database according to the unique identifier entered during login.

3. The method according to claim 2, wherein: The server verifies whether the first packaged data transmitted by the client has been tampered with; If not, the unique identifier and the first ciphertext entered during registration are stored in the database including: The server concatenates the unique identifier, public key, first ciphertext, and timestamp entered during registration in the first packaged data transmitted by the client and generates a third signature; The server verifies whether the third signature is consistent with the first signature in the first packaged data transmitted by the client, and verifies whether the locally stored public key is consistent with the public key in the first packaged data transmitted by the client; if they are consistent, the unique identifier and the first ciphertext entered during registration are stored in the database; The server verifies whether the second packaged data transmitted by the client has been tampered with; if not, obtaining the first ciphertext from the database according to the unique identifier entered during login includes: The server concatenates the unique identifier, public key, third ciphertext, and timestamp entered during login in the second packaged data transmitted by the client and generates a fourth signature; The server verifies whether the fourth signature is consistent with the second signature in the second packaged data transmitted by the client, and verifies whether the locally stored public key is consistent with the public key in the second packaged data transmitted by the client; if they are consistent, the server obtains the first ciphertext from the database according to the unique identifier entered during login.

4. The method according to claim 1, wherein Said S1 comprises: The server randomly generates two large prime numbers p and q, and satisfies gcd(pq,(p-1)(q-1))=1; Generate public and private keys based on two large prime numbers p and q and store them locally.

5. The method according to claim 4, characterized in that: The third ciphertext is calculated according to the following formula: m1=E(P′)·E(C)modn 2 Where m1 is the third ciphertext, E(P′) is the second ciphertext, C is the random challenge value, P′ is the password entered by the user when logging in, n is the product of two large prime numbers p and q, and mod is the remainder; The fourth ciphertext is calculated according to the following formula: m2=E(P)·E(C)modn 2 Among them, m2 is the fourth ciphertext, E(P) is the first ciphertext, C is the random challenge value, P is the password entered by the user when registering, n is the product of two large prime numbers p and q, and mod is the remainder.

6. A homomorphic encryption-based identity authentication system, characterized in that: include: Generation unit, used by the server to generate public and private keys and store them locally; The first encryption unit is used for the client to obtain the public key of the server and obtain the unique identifier and password entered by the user during registration; and encrypt the password using the public key to obtain a first ciphertext; A storage unit, used for the server to obtain the first ciphertext and the unique identifier entered during registration and store them in a database; The second encryption unit is used for the client to obtain the unique identifier input by the user when logging in and send it to the server; the server generates a random challenge value and binds it to the unique identifier; the server sends the random challenge value to the client; The client obtains the password entered by the user when logging in, and encrypts the password using the public key to obtain a second ciphertext; The client calculates the third ciphertext based on the second ciphertext and the random challenge value; A third encryption unit is configured to obtain, from the server, the third ciphertext and the unique identifier entered during login, and obtain the first ciphertext from the database based on the unique identifier entered during login; the server calculates the fourth ciphertext based on the first ciphertext and a random challenge value bound to the unique identifier; The verification unit is used for the server to calculate the difference ciphertext based on the third ciphertext and the fourth ciphertext; if the difference ciphertext is 0, the user identity authentication is passed and the random challenge value is deleted.

7. The system according to claim 6, characterized in that: The server obtains the first ciphertext and the unique identifier entered during registration and stores them in the database, including: The client concatenates the unique identifier, public key, first ciphertext, and timestamp entered during registration to generate the first signature; The client sends the unique identifier, public key, first ciphertext, timestamp, and first signature entered during registration as first packaged data to the server; The server verifies whether the first packaged data transmitted by the client has been tampered with; if not, the server stores the unique identifier and the first ciphertext entered during registration in the database; The server obtains the third ciphertext and the unique identifier input during login, and obtains the first ciphertext from the database according to the unique identifier input during login, including: The client concatenates the unique identifier, public key, third ciphertext, and timestamp entered during login to generate a second signature. The client sends the unique identifier, public key, third ciphertext, timestamp, and second signature entered during login to the server as second packaged data; The server verifies whether the second packaged data transmitted by the client has been tampered with; if not, it obtains the first ciphertext from the database according to the unique identifier entered during login.

8. The system according to claim 7, characterized in that: The server verifies whether the first packaged data transmitted by the client has been tampered with; If not, the unique identifier and the first ciphertext entered during registration are stored in the database including: The server concatenates the unique identifier, public key, first ciphertext, and timestamp entered during registration in the first packaged data transmitted by the client and generates a third signature; The server verifies whether the third signature is consistent with the first signature in the first packaged data transmitted by the client, and verifies whether the locally stored public key is consistent with the public key in the first packaged data transmitted by the client; if they are consistent, the unique identifier and the first ciphertext entered during registration are stored in the database; The server verifies whether the second packaged data transmitted by the client has been tampered with; if not, obtaining the first ciphertext from the database according to the unique identifier entered during login includes: The server concatenates the unique identifier, public key, third ciphertext, and timestamp entered during login in the second packaged data transmitted by the client and generates a fourth signature; The server verifies whether the fourth signature is consistent with the second signature in the second packaged data transmitted by the client, and verifies whether the locally stored public key is consistent with the public key in the second packaged data transmitted by the client; if they are consistent, the server obtains the first ciphertext from the database according to the unique identifier entered during login.

9. The system according to claim 6, wherein: The generating unit includes: The first generation subunit is used for the server to randomly generate two large prime numbers p and q, and satisfy gcd(pq, (p-1)(q-1)) = 1; The second generation subunit is used to generate a public key and a private key according to two large prime numbers p and q and store them locally.

10. The system according to claim 9, characterized in that: The third ciphertext is calculated according to the following formula: m1=E(P′)·E(C)modn 2 Where m1 is the third ciphertext, E(P′) is the second ciphertext, C is the random challenge value, P′ is the password entered by the user when logging in, n is the product of two large prime numbers p and q, and mod is the remainder; The fourth ciphertext is calculated according to the following formula: m2=E(P)·E(C)modn 2 Among them, m2 is the fourth ciphertext, E(P) is the first ciphertext, C is the random challenge value, P is the password entered by the user when registering, n is the product of two large prime numbers p and q, and mod is the remainder.

Citation Information

Patent Citations

  • Digital identity authentication method, equipment, device and system and storage medium

    CN109862041A

  • Privacy-protecting user registration method and device and privacy-protecting user authentication method and device

    CN114547589A

  • Identity verification method and device, storage medium and electronic equipment

    CN115766115A

  • Identity verification method, system, equipment and medium

    CN117097535A

  • Identity authentication method and system and computer equipment

    CN119520028A

Cited By

  • End-cloud collaborative data processing method, device and system and related equipment

    CN121585465A

  • An end-cloud cooperative data processing method, device, system and related equipment

    CN121585465B